SOKKAN Router · Legal
Data Processing Agreement
Draft — version 2026-10-04. Not yet approved for production. Passages marked “To be validated” are open decisions. GDPR art. 28 / Swiss FADP art. 9.
This agreement supplements the SOKKAN Router Terms of Service (the “Terms”). It applies between NINABOT Sàrl, Chemin de Riantbosson 19, 1217 Meyrin (GE), Switzerland, CHE-287.575.522 (“NINABOT”, “Processor”) and the holder of a SOKKAN Router account (the “Customer”). It takes effect when the Customer accepts the Terms. NINABOT provides a signed counterpart on request.
1. Roles
For the content sent to the API, the Customer acts as controller, or as processor on behalf of its own customers. NINABOT acts as processor, or as sub-processor of the Customer, and processes personal data only on the Customer's documented instructions. The Customer's instruction is: send each API request to a provider able to serve the requested model, within the location the Customer selected, return the result, and charge the tokens consumed. NINABOT informs the Customer if it believes an instruction infringes applicable data protection law.
For account data (e-mail address, payments, usage records), NINABOT is controller; see the Privacy Policy.
2. Details of processing
- Subject matter and nature: routing API requests to language-model inference, running or obtaining that inference, and returning the result.
- Duration: the duration of each request; the agreement lasts as long as the Customer's account.
- Categories of data: any personal data that the Customer or its users include in prompts (the API does not ask for any); request metadata.
- Data subjects: the Customer's users and persons mentioned in the content.
- Special categories: not requested. The same treatment applies if they are present.
3. No retention, no secondary use
- NINABOT processes prompts and completions in memory, for the duration of the request only. It does not write them to disk, log them or keep them, and never uses them for training, evaluation, product improvement or any other purpose.
- The
userfield of a request is not forwarded to upstream providers. - For billing, NINABOT records per request only counters: request identifier, account and API key identifiers, time, model, provider that served the request and its country, token counts (input, cached, output), cost, whether the usage was estimated, HTTP status, time to first token, total latency and number of providers tried. These records contain no request content and are kept 10 years (Swiss Code of Obligations, art. 958f).
- What each upstream provider does with request content is stated in section 6, from its own contractual terms.
4. Location of processing, chosen per request
Processing location depends on the model and on the provider that serves it. NINABOT publishes it and lets the Customer restrict it:
- Per model.
GET /v1/modelslists for each model the regions where it can be served (regions:CH= Switzerland,EU= the European Economic Area,US= the United States). The upstream providers and their countries are those listed in section 6. - Per request. The response header
x-sokkan-regionstates the region (CH,EUorUS) where the request was served. - Restriction. The header
X-Data-Location(or"provider": {"data_location": …}in the body) restricts the providers used:CH= Switzerland only;EU= the European Economic Area or Switzerland;any(default) = any provider listed for the model. If no provider of the model matches, the request is refused (HTTP 400) and sent nowhere. - Several providers per request. To avoid silent requests, a request may be sent to a second provider if the first has not started to answer within a short delay or has failed; the first answer is returned. Every provider tried is one that matches the Customer's restriction.
At the date of this version, the catalogue contains only providers located in Switzerland and in France. A provider
in another country is declared in /v1/models and added under section 6, with the notice of section 6,
before it receives traffic.
Switzerland benefits from an adequacy decision of the European Commission (GDPR art. 45), and the EEA states are recognised as adequate by Switzerland, so routing between them needs no additional safeguard. Transfers to a sub-processor in another country rely on the safeguards stated in section 6.
5. Security measures
- TLS encryption from the Customer to the network edge and from the platform to upstream providers' public endpoints; WireGuard encryption (Tailscale) between NINABOT's own servers.
- Before a request leaves the platform, credentials (API keys, access tokens, private keys) cause it to be refused, and Swiss IBANs, Swiss social security numbers and payment card numbers are masked.
- API keys and sign-in links are stored only as SHA-256 hashes; keys can be revoked at any time by the Customer.
- HTTP access logs are disabled on the API service; application logs never contain request content.
- Administrative access is restricted to NINABOT's founders and the operating tools they run, over private encrypted channels.
- Per-key rate limits, and a circuit breaker that moves a repeatedly failing provider to the end of the routing order.
- Persons authorised to process data on behalf of NINABOT are bound by confidentiality.
6. Sub-processors
The Customer authorises the following sub-processors for request content. A model provider only receives the requests routed to it under section 4.
Platform and network
- Akenes SA (Exoscale), Lausanne, Switzerland — hosting of the SOKKAN Router platform (API gateway, account and billing database) on a virtual machine in Exoscale's Geneva datacenter. Request content passes through it in memory and is not stored. Processing stays in Switzerland.
- Cloudflare, Inc., San Francisco, United States (global network) — DNS, TLS termination and network protection in front of the API. Request content passes through Cloudflare in transit. Safeguard: Cloudflare's certification under the EU–US and Swiss–US Data Privacy Framework.
- Tailscale Inc. (Canada) — coordination of the encrypted private network between NINABOT's servers. Traffic is end-to-end encrypted with keys Tailscale does not hold; Tailscale processes connection metadata only, in Canada, Germany, the United States and the United Kingdom, under standard contractual clauses for transfers to the United States.
To be validated: the production platform is not deployed yet (staging runs on NINABOT's own server in Geneva); this text describes the planned Exoscale virtual machine in Geneva. If database backups go to Cloudflare R2, as the current backup script does for SOKKAN Cloud, the backup location must be added here.
Model providers
- NINABOT Sàrl (no sub-processor) — models served on NINABOT's own GPU servers in Geneva, Switzerland
(provider
SOKKAN, countryCH, region Geneva). - Infomaniak Network SA, Rue Eugène-Marziano 25, 1227 Geneva, Switzerland — managed inference (AI Services / LLM API), for the models that Infomaniak serves. Under its LLM API terms, Infomaniak stores some data only for the time needed to process the request, keeps only billing and operating metadata, and does not use prompts or responses to train its models or in any other way; its general terms state that customer data is hosted only in datacenters in Switzerland owned by Infomaniak. Processing stays in Switzerland.
- OVH GmbH (OVHcloud group), Oskar-Jäger-Str. 173/K6, 50825 Köln, Germany, with infrastructure operated by
OVH SAS in France — managed inference (AI Endpoints, datacenter of Gravelines) and GPU instances (AI Deploy) in
OVHcloud's datacenters in France, for the models whose provider has country
FR, including those listed under providerSOKKANwith countryFR, which NINABOT serves through OVHcloud. Under OVHcloud's AI Endpoints conditions, OVHcloud has no knowledge of inputs and outputs, does not reuse them and does not back them up. Processing stays in the EEA. - Akenes SA (Exoscale) — GPU instances in Exoscale's Zurich datacenter (zone
ch-dk-2), for the models whose provider region is an Exoscale zone. Request content is processed in memory and not stored. Processing stays in Switzerland. No model is served there at the date of this version.
Account data only (no request content)
- Stripe Payments Europe, Limited (Ireland), with Stripe, Inc. (United States) — payment of credit. Stripe receives no request content. Stripe, Inc. is certified under the EU–US and Swiss–US Data Privacy Framework. Stripe, Inc. (Stripe Identity) also verifies the identity of a Customer's representative who asks to raise the top-up limits; this concerns account data only, never request content.
- E-mails (sign-in codes and links, support tickets) are sent by NINABOT's own mail server, operated by NINABOT on a virtual machine of Akenes SA (Exoscale) in Geneva, Switzerland. No third-party e-mail provider is involved; the e-mails contain no request content.
NINABOT informs the Customer by e-mail at least 14 days before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds; if no solution is found, the Customer may stop using the affected models or close its account, and NINABOT refunds the unused credit. NINABOT imposes on each sub-processor data protection obligations equivalent to this agreement, to the extent the sub-processor's standard terms allow, and remains liable for them.
To be validated: a refund of unused credit when the Customer objects to a new sub-processor (proposed; it makes the right to object real with prepaid credit). Lambda (United States) is deliberately not listed: its transfer mechanism has not been verified, and no model may be routed there before it is.
7. Personal data breach
NINABOT notifies the Customer without undue delay and in any case within 48 hours after becoming aware of a breach affecting the Customer's data, with the information available (nature, likely consequences, measures taken), and cooperates with the Customer's own notification duties (GDPR art. 33-34, FADP art. 24).
8. Assistance
Since no content is retained, NINABOT holds no end-user content to access, correct or delete. NINABOT nevertheless assists the Customer, taking into account the nature of the processing, with data subject requests, data protection impact assessments and consultations with supervisory authorities.
9. Audit
NINABOT makes available to the Customer the information necessary to demonstrate compliance with this agreement, and allows for and contributes to audits, including inspections, by the Customer or an auditor it mandates, bound by confidentiality, on 30 days' notice, at most once a year unless a breach or a supervisory authority requires otherwise. Each party bears its own costs.
10. End of processing
When the account is closed, no request content remains to be returned or deleted. Billing records are kept as stated in section 3.
11. Precedence, law and jurisdiction
This agreement prevails over the Terms for data protection matters. It is governed by Swiss law, with place of jurisdiction in Geneva; mandatory provisions of the GDPR apply where the Customer is subject to it. Liability follows the Terms.
12. Contact
NINABOT Sàrl, Chemin de Riantbosson 19, 1217 Meyrin (GE), Switzerland — [email protected].